PRIVACY POLICY
Effective date: 25/02/2026
Last updated: 25/02/2026
1. WHO WE ARE
Enterprise19
Unit 4a, Romans Business Park
Farnham, Surrey, GU9 7SX
United Kingdom
Email: shop@post19.com
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Enterprise19 is the Data Controller of your personal data.
2. WHAT PERSONAL DATA WE COLLECT
We may collect and process the following categories of personal data:
Information You Provide Directly
-
Name
-
Billing and delivery address
-
Email address
-
Phone number
-
Payment details (processed securely via payment providers)
-
Account login information (if applicable)
-
Communications you send to us
Information Collected Automatically
-
IP address
-
Browser type and version
-
Device information
-
Website usage data
-
Cookies and tracking technologies
Transaction Information
-
Order history
-
Products purchased
-
Returns and refunds
3. OUR LAWFUL BASIS FOR PROCESSING (UK GDPR ARTICLE 6)
We only process your data where we have a lawful basis:
Contract
To:
-
Process and deliver your order
-
Take payment
-
Manage returns and refunds
-
Provide customer support
Legal Obligation
To:
-
Comply with HMRC tax laws
-
Prevent fraud
-
Maintain required financial records
Legitimate Interests
To:
-
Improve our website and services
-
Prevent fraud
-
Analyse website performance
-
Defend legal claims
We ensure our legitimate interests do not override your rights.
Consent
To:
-
Send marketing emails
-
Use non-essential cookies
You may withdraw consent at any time.
4. HOW LONG WE KEEP YOUR DATA
We retain personal data only as long as necessary:
-
Order and financial records: 6 years (UK tax law requirement)
-
Marketing data: Until you withdraw consent
-
Customer service communications: Up to 3 years
-
Website analytics data: Up to 26 months
After this period, data is securely deleted or anonymised.
5. HOW WE SHARE YOUR DATA
We share data only where necessary with trusted service providers, including:
-
Shopify Inc. (our ecommerce platform provider)
-
Payment processors (e.g. Stripe, PayPal, Shopify Payments)
-
Delivery couriers
-
Accountants and professional advisers
-
IT and hosting providers
All processors are contractually required to protect your data.
We may also disclose data if required by law.
6. INTERNATIONAL TRANSFERS
Some of our service providers (including Shopify) may process data outside the UK.
Where this occurs, we ensure safeguards are in place, such as:
-
UK International Data Transfer Agreement (IDTA)
-
Adequacy regulations approved by the UK Government
-
Standard Contractual Clauses
7. YOUR DATA PROTECTION RIGHTS
Under UK GDPR, you have the right to:
-
Access your personal data
-
Correct inaccurate data
-
Request erasure ("right to be forgotten")
-
Restrict processing
-
Object to processing
-
Data portability
-
Withdraw consent at any time
-
Not be subject to automated decision-making (where applicable)
To exercise any rights, contact: shop@post19.com
You also have the right to lodge a complaint with the UK regulator:
Information Commissioner's Office
Website: https://www.ico.org.uk
8. COOKIES
We use cookies and similar technologies.
Essential Cookies
Necessary for:
-
Shopping cart functionality
-
Secure login
-
Fraud prevention
These cannot be switched off.
Analytics Cookies
Used to analyse website performance and usage.
These are only set with your consent.
Marketing Cookies
Used to personalise advertising.
These require your prior consent.
You can manage cookie preferences via our cookie banner or browser settings.
9. MARKETING COMMUNICATIONS
We will only send marketing emails where:
-
You have opted in, or
-
You have purchased from us and have not opted out (soft opt-in under PECR).
You can unsubscribe at any time by:
-
Clicking “unsubscribe” in any email
-
Contacting shop@post19.com
10. SECURITY
We implement appropriate technical and organisational measures including:
-
SSL encryption
-
PCI-DSS compliant payment processing
-
Restricted internal access controls
-
Secure hosting infrastructure
While no online system is 100% secure, we follow recognised industry standards.
11. CHILDREN’S DATA
Our website is not intended for children under 16.
We do not knowingly collect personal data from children.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time.
Changes will be posted on this page with an updated revision date.
13. CONTACT US
If you have questions or wish to exercise your rights:
Privacy Compliance Officer
Enterprise19
Unit 4a, Romans Business Park
Farnham, Surrey, GU9 7SX
United Kingdom
Email: shop@post19.com
